4WinMobile.com

Go Back   4WinMobile.com > 4WinMobile Site > 4WM News > Old News, Press Releases, Store Notifications

Old News, Press Releases, Store Notifications Archive containing old News Threads, Press Releases and Store Notifications

Post New Thread Reply
 
Thread Tools Search this Thread Display Modes
Old 21-05-2008, 06:17 PM   #1 (permalink)
Administrator
 
windows's Avatar
 
Join Date: Sep 2005
Location: Manchester UK
Posts: 20,698
Security vunerability for Windows CE posted

A security vunerability for Windows CE posted in the US-CERT Cyber Security Bulletin.

Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted JPEG and GIF images.

For more details see National Vulnerability Database (CVE-2008-2160)

And update is available from Microsoft here.
__________________
Daron Brewood

C.E.O. 4Winmobile.com
MS MVP Mobile Devices
Device: O2 Xda Various
windows is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsors
Old 21-05-2008, 06:32 PM   #2 (permalink)
Site Moderator
 
debonairone's Avatar
 
Join Date: May 2007
Location: New Jersey, USA
Posts: 1,048
Re: Security vunerability for Windows CE posted

Ok, here we go again... how long before I truly have to worry about browsing using my device...? PLEASE LET US BE... all we wanna do is enjoy our devices, like the truly addicted people we are...
__________________
debonairone - Moderator
HTC TyTn (Hermes 200)
Suffering from Rom Flash Withdrawal Syndrome
If you enjoy this site then please ensure it's survival with a Donation or a Subscription.
debonairone is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 21-05-2008, 06:44 PM   #3 (permalink)
Administrator
 
windows's Avatar
 
Join Date: Sep 2005
Location: Manchester UK
Posts: 20,698
Re: Security vunerability for Windows CE posted

Yeah but with this one MS do seem to acknowledge it and a fix issued.
__________________
Daron Brewood

C.E.O. 4Winmobile.com
MS MVP Mobile Devices
Device: O2 Xda Various
windows is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 23-05-2008, 02:18 AM   #4 (permalink)
Site Moderator
 
debonairone's Avatar
 
Join Date: May 2007
Location: New Jersey, USA
Posts: 1,048
Re: Security vunerability for Windows CE posted

It's not the fact that the vulnerability exists, it's the fact that there are those that will exploit it that bothers me... As intelligent as they are, please put that gray matter to use for my benefit, not the opposite...

But I am grateful that M$ has acknowledged it and issued a patch...

Deb.
__________________
debonairone - Moderator
HTC TyTn (Hermes 200)
Suffering from Rom Flash Withdrawal Syndrome
If you enjoy this site then please ensure it's survival with a Donation or a Subscription.
debonairone is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 23-05-2008, 02:47 PM   #5 (permalink)
Administrator
 
windows's Avatar
 
Join Date: Sep 2005
Location: Manchester UK
Posts: 20,698
Re: Security vunerability for Windows CE posted

Yep, unfortunately there are always idiots out there who will take advanage of such things!
__________________
Daron Brewood

C.E.O. 4Winmobile.com
MS MVP Mobile Devices
Device: O2 Xda Various
windows is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsors
Old 27-05-2008, 11:06 AM   #6 (permalink)
Site Moderator
 
waveydavey's Avatar
 
Join Date: Sep 2005
Posts: 13,343
Donation Level 4 
Re: Security vunerability for Windows CE posted

I agree with Jeff, the sad fact is that some of these virus writer types are very talented individuals. If only they'd put their talent to helping the community imagine how quickly the software world could progress. They might even make a buck or two too.
__________________
Waveydavey
4WM Moderator & Reviewer.
Microsoft MVP - Windows Mobile Devices.
waveydavey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-05-2008, 01:01 PM   #7 (permalink)
Site Moderator
 
Bassey's Avatar
 
Join Date: Nov 2005
Location: Isle of Man
Posts: 3,045
Re: Security vunerability for Windows CE posted

For a long time mobile OSs have been considered far more secure than their desktop brethren. One of the (several) reasons for this was the lack of a permanant internet connection. As many people are now keeping their data connections permanantly open, thanks to all you can eat data plans, this restriction has dissappeared.

Still, devices are set up by default to ask the user before installing apps and to ask before sending data so they are pretty secure with a bit of common sense. I wonder how long it will be, though, before these things are bypassed for the sake of "ease of use", particularly in a corporate sense.

It makes huge sense to be able to bypass user interaction when deploying software, updates, sending data etc. from a Corporate standpoint. If you're deploying an update to 1000 devices you want minimum interaction. However, once the facilities are in the OS, it's only a matter of time before someone comes up with a way of exploiting it.
__________________
---
Ericsson R380, Nokia 7650, SE T68, SE P800, SE P900, XDA II, XDA IIs, XDA MiniS +2GB mSD, HTC Touch Cruise + 8GB MicroSDHC
Bassey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-05-2008, 03:07 PM   #8 (permalink)
Site Moderator
 
bydandie's Avatar
 
Join Date: Sep 2005
Posts: 1,503
Re: Security vunerability for Windows CE posted

Is it just me, or what was the point of having the update facility in WM? The patch has to be built into the base build, so HTC would have to package it into their ROM builds AFAIK.

It also requires user input as below

"Access Vector: Network exploitable , Victim must voluntarily interact with attack mechanism"

So in terms of bang for buck it really isn't the type of thing that would be attractive to cybercrime when there are far better vulnerable systems with a guaranteed fast internet connection.
__________________
Bydandie
Moderator
4Winmobile.com

Previous devices: T-Mob MDA Touch 256Mb, T-Mob MDA Touch 128Mb, T-Mob Ameo (WM6), Qtek v1605, T-Mob Vario, Moto MPx220, O2 XDAII, Dell Axim X5
bydandie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 28-05-2008, 12:14 AM   #9 (permalink)
Site Moderator
 
debonairone's Avatar
 
Join Date: May 2007
Location: New Jersey, USA
Posts: 1,048
Re: Security vunerability for Windows CE posted

Ha... Good point... I even tried using the update facility, just to see what would be updated, at least while the cooks left it in the rom...

As for the why would anyone bother with WM devices, the singular (not to be confused with Cingular) question would be, "I wonder if I can..?" And once they can, everyone can...
__________________
debonairone - Moderator
HTC TyTn (Hermes 200)
Suffering from Rom Flash Withdrawal Syndrome
If you enjoy this site then please ensure it's survival with a Donation or a Subscription.
debonairone is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 28-05-2008, 07:29 AM   #10 (permalink)
Site Moderator
 
bydandie's Avatar
 
Join Date: Sep 2005
Posts: 1,503
Quote:
Originally Posted by debonairone View Post
Ha... Good point... I even tried using the update facility, just to see what would be updated, at least while the cooks left it in the rom...

As for the why would anyone bother with WM devices, the singular (not to be confused with Cingular) question would be, "I wonder if I can..?" And once they can, everyone can...
The point though Deb is that almost all attacks have been for financical gain over the past four yeafs. Almost all attacks form part of the botnet cycle to gather information from systems. The fact remains that exploits like GDI rely on a feaure-rich browser and enough bandwidth to download the payload. Neither of which is prevalent in WM devices and the market share of WM is miniscule compared to all other smartphones.

Posted via Mobile Device
bydandie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsors
Post New Thread Reply  

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Friends of 4WM
Spb


All times are GMT. The time now is 12:03 AM.

Sponsors



 


Design by: vBulletin Skins Zone
Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
(c) Daron Brewood - www.4winmobile.com 2004-2008
Ad Management by RedTyger


Page generated in 0.24460 seconds with 12 queries